Skip to content

Artifact Security Scanning Failing due to private keys present #904

Description

@ministryofjay-cisco

In some environments security programs scan build artifacts, vm disks, s3 buckets, etc.

If a piece of software is using/importing pycryptodome then the python package is included in the artifact. pip install pycryptodome includes the SelfTest directory within the distribution. Within the SelfTest/PublicKey there are a few files test_import_<algorithm>.py which include test private keys hardcoded in the source.

The security software is detecting the presence of these private keys and raising an alert. Does it make sense to include the test files within the PYPI package?

Can these be removed to prevent security scans from detecting them.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions